Open Connect → API Proxy
/websites/:id/proxy— add a connection (base URL + optional vault secret).Add a route
Give it a
routeIdused in code (e.g.library.write), allowed methods, path allowlist, and an auth mode.Call from the SDK
await macro.proxyFetch('library.write', { path: '/books', method: 'POST', nodeKey: 'library.admin', // or closestPrivateBlockKey(btn) body: { title: 'New book' }, })
Auth modes
routeAcl— same model as block ACL: allow roles or users (includingeveryone), deny individual users. No separate “any editor” mode — alloweveryoneinstead.capability— auto permissionPROXY_<routeId>; enable it under Roles → API Proxy (no free-text key).fromNode— live Node ACL for anodeKey(caller-supplied or fixed). Pairs with Private Blocks.
Private Block + Proxy
Put admin UI inside
macro/private-block, set route auth to fromNode, and pass the wrapper (or any) macro key as nodeKey. Visibility and writes share the same ACL.